fix: reject duplicate legacy DWH records
This commit is contained in:
@@ -516,7 +516,7 @@ func validateLegacyMultiplicity(active, revoked []storedRecord) error {
|
||||
revokedCount++
|
||||
}
|
||||
}
|
||||
if activeCount > 1 || revokedCount > 1 || activeCount+revokedCount > 2 {
|
||||
if activeCount > 1 || revokedCount > 1 || activeCount+revokedCount > 1 {
|
||||
return integrity(errors.New("multiple legacy records"))
|
||||
}
|
||||
return nil
|
||||
|
||||
@@ -289,6 +289,22 @@ func TestFindLegacyAllowsOneAndRejectsMultipleRecords(t *testing.T) {
|
||||
t.Fatal("FindLegacy() error = nil, want multiple-legacy integrity refusal")
|
||||
}
|
||||
})
|
||||
t.Run("active and revoked legacy records", func(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
store := openStore(t, root)
|
||||
legacy := syntheticLegacyRecord()
|
||||
if err := store.Add(legacy); err != nil {
|
||||
t.Fatalf("Add() error = %v", err)
|
||||
}
|
||||
revokedAt := legacy.CreatedAt.Add(time.Hour)
|
||||
writeRecord(t, root, StateRevoked, legacy.KeyID+".json", marshalRecord(t, revokedRecord(legacy, revokedAt, "synthetic")), 0o640)
|
||||
if _, err := store.FindLegacy(); !errors.Is(err, ErrIntegrity) {
|
||||
t.Fatalf("FindLegacy() error = %v, want ErrIntegrity", err)
|
||||
}
|
||||
if err := store.Check(); !errors.Is(err, ErrIntegrity) {
|
||||
t.Fatalf("Check() error = %v, want ErrIntegrity", err)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
func TestConcurrentAddDoesNotOverwriteAndFindNeverReadsPartialRecord(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user